Reducing "gate" counts for Kyber-512 contradicting NIST's calculation
blog.cr.yp.to
blog.cr.yp.to
If NIST really is up to no good on behalf of US intelligence agencies, it's reasonable to believe they'd be doing everything they can to prevent strong post-quantum crypto.
Also, here's an idea I had: let's say you wrapped a plaintext in three different encryption algorithms authored in adversarial countries. Even if you assume all three are backdoored by their creators, you'd have something that could only be unwrapped if the three adversarial countries worked together. Is there anything out there that does this?
In practice post-quantum encryption is always combined with normal encryption so this sorta thing should become even more common in the future.
Ray Perlner (NIST PQC), Re: Kyber security level? https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/W2VO...
Christopher J Peikert, Re: Kyber security level? https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/W2VO...
Matthew Green on Mastodon https://ioc.exchange/@matthew_d_green/111227593416987176
tptacek on HN https://news.ycombinator.com/item?id=37874682
Personally, I am woefully unqualified to judge the intricacies of attack cost estimation myself, but I have followed enough of the process to find some of the conspiracy claims risible. For example, that NIST made a graph a little smaller on a slide to "deemphasize" it (search for "thinner red bars" in https://blog.cr.yp.to/20231003-countcorrectly.html).
Moreover, I fail to understand why NIST would pick a weak algorithm (designed by independent researchers) to secure the data of US federal agencies and industry. This is critically different from Dual_EC_DRBG in that there is nowhere to hide a NOBUS (https://en.wikipedia.org/wiki/NOBUS) backdoor, so it would be a ridiculous bet that no one else in the world will find the weakness in the next fifty years.
The one bit of color I will add is that every community of cryptographers I am in has had enough of this, as far as I can tell, and is not taking Bernstein seriously anymore. The most common reactions are eyerolls and popcorns. As I said before (https://news.ycombinator.com/item?id=37868974), I am worried that Bernstein has increasingly argued in bad faith and alienated his peers (through spurious accusations, personal attacks, endless never-retracted arguments, and legal threats) to the point that they're unwilling to engage with him, which from the outside can look like his points are unrefutable. Like Matthew Green, I am worried about what that will do to confidence in modern cryptography, given Bernstein's following.
Also, they analyse gate times rather than ALU in estimations to account for someone producing a dedicated chip for cracking the cipher, right?